Berlin Has Until Today Before Rhysida May Dump 5.7 TB of Stolen Government Data
- The Mess: Berlin refused to pay Rhysida, and today the ransomware gang’s deadline expires. The attackers claim they stole roughly 5.7 TB of data from the Berlin state network and are threatening to publish or sell it.
This is no longer just a ransomware claim sitting on a leak site.
Berlin’s government confirmed that the attackers are attempting to extort the state and that stolen data is involved. The city has warned that the material could include personal information belonging to government employees, Berlin residents and companies. Authorities say they cannot rule out publication on September 4.
Rhysida reportedly demanded 30 Bitcoin, roughly €2 million at the time of the demand.
Berlin’s answer was simple: no payment.
The attackers then put the alleged stolen data up for auction with a starting price of 30 BTC and a deadline set for today.
The claimed haul is huge.
Rhysida says it obtained approximately 5.7–5.79 TB of files, including tens of thousands of contracts, emails, phone numbers, passwords and other sensitive material. Reuters reported that the gang claimed to have around 46,500 contracts in the stolen dataset.
Berlin is being careful about what it confirms.
Officials have not independently verified every item claimed by Rhysida, and forensic investigators are still determining the full scope of the compromise.
But the government has already confirmed that data actually left the network.
The known exfiltration window ran from August 7 to August 12, before two affected Senate administrations were isolated from the state network on August 14. Berlin later confirmed additional data loss from the Senate Department for Mobility, Transport, Climate Protection and the Environment.
The attack also created an awkward security timeline.
Berlin detected the incident and began isolating systems, but investigators continued working to determine exactly what had been taken. Parts of the administration’s network were disconnected while forensic teams scanned the environment.
By September 3, the government was explicitly warning that the stolen material could include personal data belonging to employees, citizens and companies.
Authorities also said they currently have no evidence that the state network remains infiltrated, although forensic analysis is still underway.
There is another important line in Berlin’s latest statement: investigators are checking whether additional data may have been exfiltrated.
That means today’s deadline is not necessarily the end of the incident.
If Rhysida publishes the files, the problem changes immediately.
A ransomware incident becomes a mass data-distribution event.
Stolen government contracts can expose suppliers and business relationships. Internal emails can reveal operational details. Credentials can create secondary attacks. Personal information can feed phishing, identity fraud and targeted social engineering.
And the potentially sensitive material is not limited to ordinary citizen records.
Earlier reporting indicated that the stolen dataset may contain information connected to government operations and critical infrastructure. Berlin has stressed that election infrastructure was not compromised, which matters because the city’s state election is scheduled for September 20.
Berlin is therefore facing a particularly unpleasant choice.
Pay the criminals and hope they honor a promise they have no reason to honor — or refuse and prepare for publication.
The government chose the second option.
- The Damage: If Rhysida publishes the claimed dataset, thousands of government documents and potentially sensitive personal information could become freely available to criminals, researchers and anyone willing to redistribute it.
- The Fix: Berlin is not paying the ransom; affected organizations and individuals should prepare for credential resets, phishing campaigns and secondary attacks if the stolen data appears online.
Bugstoday Opinion
The interesting part is not that Rhysida demanded money.
That’s ransomware 101.
The interesting part is what happens when a government says no and the attackers actually have the data.
At that point, encryption becomes almost irrelevant.
The criminals don’t need to keep a server locked. They just need to press publish.
And if the claimed 5.7 TB is real, Berlin could spend months dealing with the consequences of one decision made inside its network weeks ago.
Today is the deadline.
Tomorrow could be the leak.
Today’s Bugs. Tomorrow’s Breaches.
Technical Sources
- Berlin Senate Chancellery — Current Situation After the ICT Incident
- Berlin Senate Chancellery — Statement on the Extortion Attempt
- Reuters — Rhysida Claims Berlin Government Data Theft
- BleepingComputer — Berlin Confirms Data Theft After Rhysida Attack
- Tagesschau / RBB — Berlin Cyberattack Updates




